> TODAY'S SUMMARY (87 articles)
Today's cybersecurity landscape highlights several critical threats and trends. A major data breach in Denmark has compromised the personal information of approximately 8.8 million individuals, raising concerns over third-party access to sensitive government databases. In the U.S., a ransomware attack on the University of Illinois Chicago's medical school has resulted in the theft of information from its servers. Additionally, Citrix is facing serious challenges as attackers exploit a newly discovered zero-day vulnerability in its NetScaler products, prompting CISA to issue warnings about potential system outages. On the software front, Debian's latest kernel security update reveals over a thousand vulnerabilities, urging users to patch their systems promptly. Meanwhile, Google has suspended its open-source bug bounty program due to an influx of AI-generated vulnerability reports, reflecting ongoing challenges in managing AI's impact on cybersecurity.
|
// AI-powered summary generated at 16:00
De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
Une vulnérabilité a été découverte dans Laravel. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.
L'entreprise AVBOB Funeral Services a confirmé avoir été victime d'une cyberattaque par des acteurs malveillants externes, entraînant une perturbation de ses plateformes et services numériques. L'entreprise a mobilisé des équipes techniques et des partenaires spécialisés pour rétablir les fonctionna...
De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
De multiples vulnérabilités ont été découvertes dans Spring Micrometer. Elles permettent à un attaquant de provoquer un déni de service à distance.
Le district scolaire de New York (New York City Public Schools) enquête sur deux incidents de cybersécurité distincts. Le premier concerne un logiciel malveillant détecté sur des ordinateurs d'un laboratoire partagé dans un campus de Manhattan, qui a été immédiatement supprimé. Le second concerne un...
Le collège Reynella East a été victime d'une cyberattaque majeure qui a paralysé l'intégralité de son système informatique. Cet incident a potentiellement mis en danger les informations personnelles des étudiants.
Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system, which could result privilege escalation, information disclosure, SQL injections, LDAP authentication bypass, cross-site scripting or spreadsheet (CSV/formula) injection. For the oldstable...
iRhythm Holdings a révélé un incident de cybersécurité impliquant un accès non autorisé à des données. L'activité non autorisée a été identifiée le 8 juin, et la société a lancé une enquête avec des experts externes. Bien qu'une demande de rançon ait été reçue le 9 juin, iRhythm a confirmé que l'inc...
Le Conseil municipal d'Alexandrie a confirmé avoir détecté un incident de sécurité informatique lié à une attaque par ransomware le 8 juin 2026. Le Conseil a immédiatement activé son plan de réponse, informé les autorités compétentes (y compris l'Autorité de protection des données) et lancé une enqu...
Microsoft has created an open-source fork of Windows Terminal called "Intelligent Terminal," and it allows you to use AI directly inside Terminal without interfering with the regular session. [...]
La ville d'Acworth a été victime d'une cyberattaque contre certains de ses systèmes informatiques le 8 juin 2026. Les services municipaux continuent de fonctionner normalement et aucune opération quotidienne n'a été affectée selon les autorités. Les forces de l'ordre ont été informées et mènent une...
Navient Corporation, une entreprise américaine de services de prêts étudiants, a subi un incident de cybersécurité où le cabinet d'avocats tiers qui lui fournit des services a été victime d'une attaque par rançongiciel. Cette attaque a entraîné la fuite de données personnelles de prêteurs, incluant...
Multiple vulnerabilities were discoverd in Nginx, a high-performance web and reverse proxy server, which could result in remote code execution, denial of service or memory disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 1.22.1-9+deb12u8.
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 149.0.7827.53-1~deb12u1.
New samba packages are available for Slackware 15.0 to fix security issues.
ShinyHunters leaked 234 GB of data allegedly stolen from DentaQuest after failed negotiations, potentially impacting 2.6 million people. The ShinyHunters extortion group has published a 234 GB archive of data allegedly stolen from dental benefits administrator DentaQuest. The cybercrime gang added t...
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Malware Targeting WordPress Abuses Steam Community Profiles for Command & Control Operations Legitimate-Looking Codex Remote UI Secretly Stea...
A new variant of the Gafgyt botnet called C0XMO is targeting DD-WRT router firmware and can move to other device types with various CPU architectures. [...]
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. U.S. CISA adds SolarWinds Serv-U flaw to its Know...